Privacy Policy
TYCHR PRIVATE LIMITED
1. Introduction
This Privacy Policy explains how TYCHR PRIVATE LIMITED ("TYCHR", "we", "us", "our") collects, uses, stores, shares, and protects personal data when you access our website at tychr.com, any TYCHR sub-domain, mobile or tablet application, learning platform, or virtual classroom (together, the "Platform"), or purchase or receive any tutoring, assessment, counselling, or related service from us (the "Services").
This Policy is prepared with reference to the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 and rules made under it.
For the personal data described here, TYCHR is the Data Fiduciary. You (and the student) are Data Principals. We decide the purposes and means of processing, and we are accountable for compliance.
Important: Where the student is under 18 years of age, "you" means the parent or lawful guardian entering into this agreement on the student's behalf. That parent or guardian is personally responsible for all obligations under it, including consent for data processing and payment.
2. Personal Data We Collect
We collect the following categories of personal data:
2.1 Identity and Contact Data
- Name of student and parent or guardian
- Date of birth
- Age
- Gender (if you provide it)
- Postal address
- Country
- Email address
- Telephone and WhatsApp number
- Emergency contact
2.2 Academic Data
- School, board, curriculum
- Year group
- Subjects and levels
- Prior grades
- Predicted grades
- Assessment results
- Coursework and assignments
- Attendance records
- Tutor feedback
- Progress reports
- Diagnostic and psychometric test results
2.3 Transaction Data
- Enrolment and package details
- Hours purchased and used
- Invoices
- Payment references
- Bank or payment-instrument details to the extent needed to receive and reconcile payment
- GST and tax details
- Refund records
2.4 Session and Content Data
- Recordings of sessions (audio, video, screen and whiteboard)
- Chat messages
- Uploaded files
- Questions asked
- Work submitted for review
2.5 Technical and Usage Data
- IP address
- Device and browser type
- Operating system
- Device identifiers
- Log files
- Pages viewed
- Features used
- Session duration
- Referring URL
- Approximate location derived from IP
- Cookie identifiers
2.6 Communications Data
- Enquiries
- Support tickets
- Email and messaging correspondence
- Call notes
- Feedback and complaints
2.7 Marketing Data
- Your consent choices
- Where you have given separate consent: photographs, images, video, first name, school, and results used in marketing (see Section 10 below)
2.8 Sources of Collection
We collect this data from:
- You directly
- The student
- A parent or guardian
- A school or agent who refers you
- Automatically through the Platform
3. Why We Process Your Data and Our Lawful Basis
| Purpose | Data Used | Lawful Basis under the DPDP Act |
|---|---|---|
| Register you and create an account | Identity, contact | Consent |
| Deliver tutoring and assessment | Identity, academic, session | Consent / performance of the service you requested |
| Allocate tutors and schedule sessions | Identity, academic | Consent |
| Take payment, invoice, reconcile, meet tax duties | Transaction, identity | Consent; legal obligation |
| Record sessions for quality, safeguarding and revision | Session data | Consent |
| Support, respond to queries, handle complaints | Contact, communications | Consent |
| Report progress to you as parent or guardian | Academic | Consent |
| Secure the Platform, prevent fraud and misuse | Technical, usage | Legitimate uses under the Act; legal obligation |
| Improve and develop the Services, analytics | Technical, usage, aggregated academic | Consent; aggregated or de-identified data where possible |
| Send service messages (schedules, invoices, changes) | Contact | Consent / necessary to deliver the service |
| Send marketing about our other services | Contact, marketing | Separate, specific consent |
| Use a student's image, name or result in marketing | Marketing | Separate, specific, verifiable consent — see Section 10 |
| Comply with law, respond to lawful requests, establish or defend claims | As required | Legal obligation |
4. Children's Data
This section reflects Section 9 of the DPDP Act and applies to every student under 18.
a. We process a child's personal data only with the verifiable consent of a parent or lawful guardian. We take reasonable steps to verify that the person giving consent is in fact the parent or guardian and is an identifiable adult.
b. We do not undertake tracking or behavioural monitoring of children, and we do not direct advertising at children.
c. We do not process a child's personal data in a way likely to cause any detrimental effect on the child's well-being.
d. A parent or guardian may at any time withdraw consent, access the child's data, request correction, or request erasure, by writing to the Grievance Officer (see Section 14).
e. The same protections apply to a person with a disability who has a lawful guardian.
f. Where you tell us a student is 18 or over, we rely on that statement. If you give us a child's data without parental consent, tell us immediately and we will delete it.
5. Who We Share Your Data With
We do not sell, rent or trade your personal data.
We share it only as follows, and only to the extent necessary:
a. Tutors and academic staff — the student's name, level, subject, academic history and progress, so they can teach.
b. Processors acting on our instructions — hosting and cloud infrastructure, video and classroom providers, payment gateways and banks, email, messaging and communication providers, analytics providers, customer-support tools, accounting and tax advisers. Each is bound by contract to protect the data and to process it only on our instructions.
c. Professional advisers — lawyers, auditors, insurers, under duty of confidentiality.
d. Authorities — where required by law, court order, or a lawful request, and to establish, exercise or defend legal claims.
e. In a corporate transaction — a buyer or successor in a merger, acquisition or restructuring, subject to this policy.
A current list of categories of processors is available on request from the Grievance Officer.
6. Transfers Outside India
We may process and store personal data on servers located outside India, and our processors may be located outside India. Where we do so, we transfer only to countries not restricted by the Central Government under the DPDP Act, and we put appropriate contractual safeguards in place.
7. Cookies and Similar Technologies
a. We use cookies, pixels, local storage and similar technologies to keep you signed in, remember preferences, secure the Platform, measure usage, and (with your consent) support marketing.
b. Strictly necessary cookies are required for the Platform to function. Analytics and marketing cookies are used only where you consent.
c. You can manage or disable cookies through your browser settings or our cookie banner. Disabling some cookies may affect functionality.
8. How Long We Keep Your Data
| Data Type | Retention Period |
|---|---|
| Account and enrolment records | Duration of the engagement and a reasonable period afterwards |
| Financial records, invoices, tax | 8 years, as required by Indian tax and company law |
| Session recordings | A limited period from the session, unless retained for an open complaint or investigation |
| Academic records and progress reports | Duration of the engagement and a reasonable period afterwards |
| Marketing consent records | Duration of consent and a reasonable period afterwards, to evidence compliance |
| Support and complaint records | A reasonable period from closure |
| Technical logs | A limited period |
We delete or irreversibly anonymise personal data when it is no longer needed, unless law requires us to keep it.
9. Security
a. We implement reasonable technical and organisational measures appropriate to the risk, including:
- Encryption in transit
- Access controls on a need-to-know basis
- Authentication
- Logging
- Secure development practices
- Vendor due diligence
- Staff confidentiality obligations
- Periodic review
b. We maintain a personal data breach response process. If a breach occurs, we will notify the Data Protection Board of India and each affected Data Principal, in the form and within the timelines required by the DPDP Act.
c. No system is perfectly secure. You must keep your credentials confidential and tell us at once if you suspect compromise.
10. Use of Images, Names and Results in Marketing
We treat this as a separate consent, not covered by acceptance of our Terms of Service.
a. We will not publish a student's photograph, video, name, school or examination results in any marketing material — including our website, social media, advertisements, brochures or presentations — unless we hold a specific, written, opt-in consent for that use.
b. For a student under 18, that consent must be given by a parent or lawful guardian and must be verifiable.
c. The consent request will state exactly what will be used, where it will appear, and for how long. Consent is optional. Refusing it does not affect admission, fees, tutor allocation or service in any way.
d. You may withdraw this consent at any time, by writing to contact@tychr.com. We will remove the material from channels under our control within a reasonable time. Material already printed, cached, or re-shared by third parties may persist, and we will use reasonable efforts to have it removed.
e. Withdrawal does not affect the lawfulness of use before withdrawal.
11. Your Rights Under the DPDP Act
You have the right to:
a. Access — obtain a summary of the personal data we process about you, the processing activities, and the identities of other Data Fiduciaries and processors with whom it has been shared.
b. Correction and completion — have inaccurate or misleading data corrected, incomplete data completed, and data updated.
c. Erasure — have personal data erased where it is no longer needed for the purpose and retention is not required by law.
d. Grievance redressal — a readily available means of raising a complaint with us (see Section 14).
e. Nominate — nominate another individual to exercise your rights in the event of death or incapacity.
f. Withdraw consent — at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of prior processing, and we may be unable to continue providing the Services without the data necessary to deliver them.
To exercise any right, write to the Grievance Officer (see Section 14) from your registered email address. We will verify your identity and respond within the time required by law. These rights are free of charge; we may charge a reasonable fee for manifestly unfounded or repetitive requests.
12. Your Duties as a Data Principal
The DPDP Act places duties on you. You must:
a. comply with applicable law when exercising your rights;
b. not impersonate another person when providing personal data;
c. not suppress material information when providing personal data for any document, identifier or proof of identity or address;
d. not register a false or frivolous grievance or complaint;
e. furnish only information that is verifiably authentic when exercising the right to correction or erasure.
Breach of these duties may attract a penalty under the Act.
13. Changes to This Privacy Policy
a. We may update this Privacy Policy to reflect changes in our practices, Services, or applicable law.
b. The updated version will be posted on the Platform with a new effective date. Where a change materially affects your rights or obligations, we will give you reasonable advance notice by email or through the Platform.
c. Continued use after the effective date constitutes acceptance. If you do not accept a change, stop using the Services and contact us about unused hours.
d. Where a change requires fresh consent under the DPDP Act, we will ask for it separately. Continued use alone will not be treated as consent to a new processing purpose.
14. Grievance Officer and Data Protection Contact
In accordance with the Information Technology Act, 2000 and the rules made under it, and the DPDP Act, 2023:
Grievance Officer
Email: contact@tychr.com
We will acknowledge a grievance promptly and resolve it within the timelines required by law.
If you are not satisfied with our response, you may complain to the Data Protection Board of India in the manner prescribed under the DPDP Act.
15. Contact
TYCHR PRIVATE LIMITED
Email: contact@tychr.com
By creating an account, submitting an enrolment form, making a payment, or using the Services, you acknowledge that you have read and understood this Privacy Policy and you consent to the collection, use, and disclosure of personal data as described, subject to the separate consents identified in Section 4 (children's data) and Section 10 (marketing use of images, names and results).
